package com.whimscrew.user.config;


import org.springframework.context.annotation.Configuration;
import org.springframework.http.HttpMethod;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.oauth2.config.annotation.web.configuration.ResourceServerConfigurerAdapter;

@Configuration
public class ResourceServerConfiguration extends ResourceServerConfigurerAdapter {
    @Override
    public void configure(HttpSecurity http) throws Exception {
          //只有管理员角色有权限操作匹配的URL端点（忽略端点的请求方法类型）
            http
                .authorizeRequests()
                .antMatchers(HttpMethod.GET, "/v1/user/**")
                .hasRole("ADMIN")
                .anyRequest()
                .authenticated();
    }
}
